PT-2020-7062 · Smf · Smf
Brian Martin
+1
·
Published
2020-01-15
·
Updated
2020-01-23
·
CVE-2009-5068
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SMF versions through v2.0.3
Description
The issue allows co-admins in shared SMF deployments to read arbitrary files on the filesystem, potentially gaining new privileges by accessing sensitive information such as database passwords stored in settings.php. This is particularly concerning in configurations where co-admins are not fully trusted.
Recommendations
For versions through v2.0.3, update to a version newer than v2.0.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files such as settings.php to minimize the risk of exploitation.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smf